Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Iteration is valid, but what is this about "triple salting"?

Googling "triple salted" sha -gox gives me 13 results, of which 3 are about caramel cupcakes and none are serious evaluations of such an approach. It sounds like homebrew security.



I can't see how it could mean anything at all. Your password is either salted or it isn't, a hash can't really be said to have multiple salts. Maybe they're using different salts in their various rounds of hashing, can't see how that would provide any more security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: